mirror of
https://github.com/privacyguides/privacyguides.org.git
synced 2026-07-27 10:51:41 +00:00
Compare commits
12
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4a3e1ab486
|
||
|
|
a71e057966 | ||
|
|
db20f733e8 | ||
|
|
18a5685941 | ||
|
|
e0f303227b | ||
|
|
0bace87733 | ||
|
|
73db426f28 | ||
|
|
0295ab4818 | ||
|
|
cf5678ed08
|
||
|
|
0ca54e081d
|
||
|
|
690b22f3b5 | ||
|
|
5219131f7e |
@@ -18,6 +18,7 @@
|
||||
# FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
# IN THE SOFTWARE.
|
||||
|
||||
$schema: https://raw.githubusercontent.com/DavidAnson/markdownlint/v0.40.0/schema/markdownlint-config-schema.json
|
||||
default: true
|
||||
line-length: false
|
||||
ul-indent:
|
||||
|
||||
@@ -128,7 +128,7 @@ After making any necessary changes, click **Delete data**.
|
||||
|
||||
## Clearing Browsing Data on Microsoft Edge
|
||||
|
||||
Finally, we will finish this tutorial with Microsoft Edge. Start by launching the browser. On the upper right-hand corner, click on the **three-dots icon**. Next, click **Settings**.
|
||||
Finally, we will finish this tutorial with Microsoft Edge. Start by launching the browser. On the upper right-hand corner, click on the **three-dots icon**. Next, click **Settings**.
|
||||
|
||||

|
||||
|
||||
@@ -138,7 +138,7 @@ In the settings page, navigate to **Privacy, Search, and Services**
|
||||
|
||||
Under **Delete Browsing Data**, click on **Choose What to Clear**.
|
||||
|
||||

|
||||

|
||||
|
||||
Modify the time range and data to be deleted. Afterwards, click **Clear Now**.
|
||||
|
||||
|
||||
@@ -409,7 +409,7 @@ There are many ways to help Tor survive and thrive! You can help by:
|
||||
- [Proton Mail](https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/)
|
||||
- [Tor Project](http://2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion)
|
||||
|
||||
***
|
||||
---
|
||||
|
||||
For more in-depth information about Tor, you can consult our [Tor Overview](https://www.privacyguides.org/en/advanced/tor-overview/).
|
||||
|
||||
|
||||
@@ -122,7 +122,7 @@ That being said, if you need advanced features, you might want to [pay](https://
|
||||
|
||||
Alternatively, if you do not need any advanced features but would like to support the project, you could use the free plan and [donate](https://keepassium.com/donate/) a fix amount to KeePassium.
|
||||
|
||||
#### Rent-to-own
|
||||
### Rent-to-own
|
||||
|
||||
Something interesting about KeePassium Premium's plan is that it offers a "[rent-to-own](https://support.keepassium.com/kb/license-rent-own/)" license. This means that if you pay for a KeePassium subscription for 12 months or more, you will always "own" the features you've paid for, even if you stop paying.
|
||||
|
||||
|
||||
@@ -329,7 +329,7 @@ From the Nginx Proxy Manager browser interface, click **Hosts**, **Proxy Hosts**
|
||||
| `monerod-rpc.<domain>` | `http` | `<hostname>` | `18089` |
|
||||
| `monero-lws.<domain>` | `http` | `<hostname>` | `18090` |
|
||||
|
||||
For each entry, enable **Block common exploits**. Configure the SSL settings with **Request a new SSL Certificate**, **Force SSL** enabled, and **HTTP/2 Support** enabled.
|
||||
For each entry, enable **Block common exploits**. Configure the SSL settings with **Request a new SSL Certificate**, **Force SSL** enabled, and **HTTP/2 Support** enabled.
|
||||
|
||||
Optionally assign an access list.
|
||||
|
||||
|
||||
@@ -208,7 +208,7 @@ If you or someone you know is in one of the situations described above, these ad
|
||||
|
||||
**Trans Peer Support** :material-arrow-right-bold: [Trans Lifeline Hotline](https://translifeline.org/hotline/) Phone number US: 1-877-565-8860 / Canada: 1-877-330-6366
|
||||
|
||||
**Stalking Victim Support** :material-arrow-right-bold: US: [SafeHorizon](https://www.safehorizon.org/get-help/stalking/) / Canada: [The Canadian Resource Centre for Victims of Crime](https://crcvc.ca/wp-content/uploads/2021/09/Cyberstalking-_DISCLAIMER_Revised-Aug-2022_FINAL.pdf)
|
||||
**Stalking Victim Support** :material-arrow-right-bold: US: [SafeHorizon](https://www.safehorizon.org/get-help/stalking/) / Canada: [The Canadian Resource Centre for Victims of Crime](https://crcvc.ca/wp-content/uploads/2021/09/Cyberstalking-_DISCLAIMER_Revised-Aug-2022_FINAL.pdf)
|
||||
|
||||
**Domestic Violence Victim Support** :material-arrow-right-bold: US: [The National Domestic Violence Hotline](https://www.thehotline.org/) Phone number: 1-800-799-7233 / Canada: [Canadian resources by situation and province](https://www.canada.ca/en/public-health/services/health-promotion/stop-family-violence/services.html)
|
||||
|
||||
|
||||
@@ -125,7 +125,7 @@ Continuing this horrifying trend, Match Group has announced this spring they are
|
||||
|
||||
If having to scan your official ID to continue using Tinder is *bad*, having to scan your eyeball from a questionable third party app is even *worse*.
|
||||
|
||||
This practice will start for Tinder in Japan, but it's likely the verification process could be expanded to all users of Match Group apps in the near future. Soon, the only way to avoid having to share biometric data with the World App to continue using your favorite dating app could be to leave the app entirely.
|
||||
This practice will start for Tinder in Japan, but it's likely the verification process could be expanded to all users of Match Group apps in the near future. Soon, the only way to avoid having to share biometric data with the World App to continue using your favorite dating app could be to leave the app entirely.
|
||||
|
||||
#### Payment information
|
||||
|
||||
|
||||
@@ -58,7 +58,7 @@ XMPP is arguably the best example of this. XMPP allows you to sign up without an
|
||||
|
||||
## Closing Thoughts
|
||||
|
||||
These three concepts are not necessarily dependent on each other. A secure product does not guarantee privacy, a private product does not guarantee security, and anonymity does not guarantee either. As I said before, there is nothing wrong with valuing one facet over another. It's also okay to use Signal even though it doesn't give you total anonymity. Just be sure you understand how a product is meant to be used and where it both shines and falls short. It would be awful to use Google thinking that it will give your communications total privacy and then your financial details get stolen by a [rogue employee](https://web.archive.org/web/20210729190743/https://nypost.com/2020/09/23/shopify-says-rogue-employees-may-have-stolen-customer-data/). Or if you used a service like Signal to organize protests in a hostile country only to be arrested once your phone number is unmasked. Know the limitations of the services you choose and decide what features are important to you. It’s also important to know that privacy and security are sliding scales. This could be an entire blog post on its own. Think of passwords. Any password – even “password” - is technically more secure than no password at all. But a 16-character randomly-generated password is even more secure than “password.” Sometimes it’s okay to find a solution that offers a blend – less privacy in one area in exchange for more security in another, or vice versa. Once again, it all comes back to your threat model, your needs, and your resources.
|
||||
These three concepts are not necessarily dependent on each other. A secure product does not guarantee privacy, a private product does not guarantee security, and anonymity does not guarantee either. As I said before, there is nothing wrong with valuing one facet over another. It's also okay to use Signal even though it doesn't give you total anonymity. Just be sure you understand how a product is meant to be used and where it both shines and falls short. It would be awful to use Google thinking that it will give your communications total privacy and then your financial details get stolen by a [rogue employee](https://web.archive.org/web/20210729190743/https://nypost.com/2020/09/23/shopify-says-rogue-employees-may-have-stolen-customer-data/). Or if you used a service like Signal to organize protests in a hostile country only to be arrested once your phone number is unmasked. Know the limitations of the services you choose and decide what features are important to you. It’s also important to know that privacy and security are sliding scales. This could be an entire blog post on its own. Think of passwords. Any password – even “password” - is technically more secure than no password at all. But a 16-character randomly-generated password is even more secure than “password.” Sometimes it’s okay to find a solution that offers a blend – less privacy in one area in exchange for more security in another, or vice versa. Once again, it all comes back to your threat model, your needs, and your resources.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -86,7 +86,7 @@ Occasionally, these recommendations are coupled with a “review” that is supp
|
||||
|
||||
At [Privacy Guides](https://privacyguides.org/), we’ve developed a set list of criteria, and we make that abundantly clear when you read our list of [recommended VPN providers](https://privacyguides.org/vpn/). We also refrain from using affiliate links. As we’ve discussed, they are fundamentally flawed ways to market a service, and using them would break the trust our community has in our recommendations.
|
||||
|
||||
We do have a sponsorship program, but all of our finances are handled in an incredibly transparent fashion. As a non-profit organization, the funding we receive cannot be used for private profit, and our community can see both where we receive money from and how it is being spent thanks to [Open Collective.](https://opencollective.com/privacyguides) Additionally, the recommendations on our site are handled by an entirely separate team of editors and contributors than the administrative team such as myself that handles the sponsorships and finances. The editors have sole control over our recommendations and operate entirely independently and on a volunteer-basis to ensure the choices we make are for the benefit of the privacy community over one individual.
|
||||
We do have a sponsorship program, but all of our finances are handled in an incredibly transparent fashion. As a non-profit organization, the funding we receive cannot be used for private profit, and our community can see both where we receive money from and how it is being spent thanks to [Open Collective.](https://opencollective.com/privacyguides) Additionally, the recommendations on our site are handled by an entirely separate team of editors and contributors than the administrative team such as myself that handles the sponsorships and finances. The editors have sole control over our recommendations and operate entirely independently and on a volunteer-basis to ensure the choices we make are for the benefit of the privacy community over one individual.
|
||||
|
||||
Ultimately, as a matter of policy our sponsors have no say over our recommendations, or whether they are recommended or a competitor is removed. We have given our community vast access to our website and internal workings to keep us in check and ensure we’re staying true to our word. This separation of management and editors is a strategy that has served the media industry well for decades, and makes all of our team and organization a more credible and trustworthy source of information.
|
||||
|
||||
@@ -98,4 +98,4 @@ Review sites should make it abundantly clear when their reviews are paid for by
|
||||
|
||||
VPN providers should consider spending less money on paid reviews, and more money on securing and validating their infrastructure. Regular security audits are one fantastic way for companies to demonstrate their dedication to keeping their users secure. We strongly believe VPN services should consider our criteria, especially in regard to the ownership of their organization. Your VPN provider should not be hiding away in Panama controlled by anonymous leadership. While you *as a user* deserve privacy, transparency should be *required* of providers if you are expected to trust them. I would not give my money to some anonymous overseas investor, why would I give all of my internet traffic to some anonymous overseas administrator?
|
||||
|
||||
Finally, when you’re choosing a VPN provider, do your own research. [Understand what a VPN actually does for you](https://www.jonaharagon.com/posts/understanding-vpns/). [Understand what it is a security audit proves](https://www.pcmag.com/article/371839/what-does-a-vpn-security-audit-really-prove), find out who owns and operates the VPN service you want to use, and make sure their policies and technologies reflect your values. [Ultimately gathering the information yourself](https://www.jonaharagon.com/posts/choosing-a-vpn/) and making an informed decision is the only way to make sure your privacy is being respected.
|
||||
Finally, when you’re choosing a VPN provider, do your own research. [Understand what a VPN actually does for you](https://www.jonaharagon.com/posts/understanding-vpns/). [Understand what it is a security audit proves](https://www.pcmag.com/article/371839/what-does-a-vpn-security-audit-really-prove), find out who owns and operates the VPN service you want to use, and make sure their policies and technologies reflect your values. [Ultimately gathering the information yourself](https://www.jonaharagon.com/posts/choosing-a-vpn/) and making an informed decision is the only way to make sure your privacy is being respected.
|
||||
|
||||
@@ -385,7 +385,7 @@ Click on the "Change PUK" button and a section will pop up. Enter a new PUK numb
|
||||
|
||||
#### 7.4. Change the default Management key
|
||||
|
||||
Click on the "Management key" button and a section will pop up. Enter or generate a "New management key" with a maximum of 64 characters. You can also change the encryption algorithm to "TDES", "AES128", "AES192", or "AES256" and add a pin protection by clicking on "Protect with PIN". Then click "Save".
|
||||
Click on the "Management key" button and a section will pop up. Enter or generate a "New management key" with a maximum of 64 characters. You can also change the encryption algorithm to "TDES", "AES128", "AES192", or "AES256" and add a pin protection by clicking on "Protect with PIN". Then click "Save".
|
||||
|
||||

|
||||
|
||||
@@ -809,7 +809,7 @@ addkey
|
||||
|
||||
When prompted with "Please select what kind of key you want" type `8`.
|
||||
|
||||
You will be asked to toggle on or off some subkey options. Here, we will generate all 3 subkeys at once, but adjust this step to your required usage. You might also need different encryption algorithms for different subkeys (see options available from the previous **`gpg`** program question).
|
||||
You will be asked to toggle on or off some subkey options. Here, we will generate all 3 subkeys at once, but adjust this step to your required usage. You might also need different encryption algorithms for different subkeys (see options available from the previous **`gpg`** program question).
|
||||
|
||||
<div class="admonition tip" markdown>
|
||||
<p class="admonition-title">To generate subkeys separately</p>
|
||||
|
||||
@@ -72,7 +72,7 @@ When organizing events and meetups in person, it's essential to keep in mind phy
|
||||
|
||||
- [x] Research if your venue has access to parking and accessible parking spots. Publish this information with your invitation.
|
||||
|
||||
- [x] Verify the venue you select is accessible to people with visual or auditory impairments. For example, check if elevators are marked with Braille or raised letters, and make sure that hosts are informed on how to communicate with guests who are deaf or hard of hearing.
|
||||
- [x] Verify the venue you select is accessible to people with visual or auditory impairments. For example, check if elevators are marked with Braille or raised letters, and make sure that hosts are informed on how to communicate with guests who are deaf or hard of hearing.
|
||||
|
||||
### Health accessibility
|
||||
|
||||
|
||||
@@ -158,7 +158,7 @@ Here are a few privacy-focused tools and services that can help you to organize
|
||||
|
||||
:video_camera: Use it to share videos with your community free from *YouTube*'s control.
|
||||
|
||||
[:octicons-home-16: Homepage](../../social-networks.md#peertube){ .md-button .md-button--primary }
|
||||
[:octicons-home-16: Homepage](https://joinpeertube.org/){ .md-button .md-button--primary }
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
@@ -22,7 +22,7 @@ Nevertheless, if we want to [**build a movement**](tip-start-alliances-not-wars.
|
||||
|
||||
- [x] Even if you are also working on a similar project, lift them up with you!
|
||||
|
||||
It doesn't matter if you are working on something comparable yourself, or if perhaps you would word their work slightly differently. As long as the message is aligned with your mission and values, spread the words of your allies loud and far!
|
||||
It doesn't matter if you are working on something comparable yourself, or if perhaps you would word their work slightly differently. As long as the message is aligned with your mission and values, spread the words of your allies loud and far!
|
||||
|
||||
By lifting each other up, we will broaden the reach of the message we share, and ultimately this serves our goals and our community too.
|
||||
|
||||
|
||||
+1
-1
@@ -43,7 +43,7 @@ To run AI locally, you need both an AI model and an AI client.
|
||||
|
||||
There are many permissively licensed models available to download. [Hugging Face](https://huggingface.co/models) is a platform that lets you browse, research, and download models in common formats like [GGUF](https://huggingface.co/docs/hub/en/gguf). Companies that provide good open-weights models include big names like Mistral, Meta, Microsoft, and Google. However, there are also many community models and [fine-tuned](https://en.wikipedia.org/wiki/Fine-tuning_(deep_learning)) models available. As mentioned above, quantized models offer the best balance between model quality and performance for those using consumer-grade hardware.
|
||||
|
||||
To help you choose a model that fits your needs, you can look at leaderboards and benchmarks. The most widely-used leaderboard is the community-driven [LM Arena](https://lmarena.ai). Additionally, the [OpenLLM Leaderboard](https://huggingface.co/spaces/open-llm-leaderboard/open_llm_leaderboard) focuses on the performance of open-weights models on common benchmarks like [MMLU-Pro](https://arxiv.org/abs/2406.01574). There are also specialized benchmarks which measure factors like [emotional intelligence](https://eqbench.com), ["uncensored general intelligence"](https://huggingface.co/spaces/DontPlanToEnd/UGI-Leaderboard), and [many others](https://nebuly.com/blog/llm-leaderboards).
|
||||
To help you choose a model that fits your needs, you can look at leaderboards and benchmarks. The most widely-used leaderboard is the community-driven [LM Arena](https://lmarena.ai). Additionally, the [OpenLLM Leaderboard](https://huggingface.co/spaces/open-llm-leaderboard/open_llm_leaderboard) focuses on the performance of open-weights models on common benchmarks like [MMLU-Pro](https://arxiv.org/abs/2406.01574). There are also specialized benchmarks which measure factors like [emotional intelligence](https://eqbench.com), ["uncensored general intelligence"](https://huggingface.co/spaces/DontPlanToEnd/UGI-Leaderboard), and [many others](https://nebuly.com/blog/llm-leaderboards).
|
||||
|
||||
## AI Chat Clients
|
||||
|
||||
|
||||
@@ -33,7 +33,7 @@ robots: nofollow, max-snippet:-1, max-image-preview:large
|
||||
|
||||
We recommend a wide variety of Android apps throughout this site. The apps listed here are Android-exclusive and specifically enhance or replace key system functionality.
|
||||
|
||||
### Shelter
|
||||
## Shelter
|
||||
|
||||
If your device is on Android 15 or greater, we recommend using the native [Private Space](../os/android-overview.md#private-space) feature instead, which provides nearly the same functionality without needing to place trust in and grant powerful permissions to a third-party app.
|
||||
|
||||
@@ -60,7 +60,7 @@ When using Shelter, you are placing complete trust in its developer, as Shelter
|
||||
|
||||
Shelter is recommended over [Insular](https://secure-system.gitlab.io/Insular) and [Island](https://github.com/oasisfeng/island) as it supports [contact search blocking](https://secure-system.gitlab.io/Insular/faq.html).
|
||||
|
||||
### Secure Camera
|
||||
## Secure Camera
|
||||
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
@@ -104,7 +104,7 @@ The image orientation metadata is not deleted. If you enable location (in Secure
|
||||
|
||||
</div>
|
||||
|
||||
### Secure PDF Viewer
|
||||
## Secure PDF Viewer
|
||||
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
|
||||
@@ -36,6 +36,7 @@ Don't install extensions which you don't immediately have a need for, or ones th
|
||||
- [:simple-firefoxbrowser: Firefox](https://addons.mozilla.org/firefox/addon/ublock-origin)
|
||||
- [:simple-googlechrome: Chrome](https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm)
|
||||
- [:fontawesome-brands-edge: Edge](https://microsoftedge.microsoft.com/addons/detail/ublock-origin/odfafepnkmbhccpbejgmiehpchacaeak)
|
||||
- [:fontawesome-brands-opera: Opera](https://addons.opera.com/en/extensions/details/ublock/)
|
||||
|
||||
</details>
|
||||
|
||||
@@ -54,7 +55,7 @@ uBlock Origin also has a "Lite" version of their extension, which offers a limit
|
||||
|
||||
- ...you don't want to grant full "read/modify website data" permissions to any extensions (even a trusted one like uBlock Origin)
|
||||
- ...you want a more resource (memory/CPU) efficient content blocker[^1]
|
||||
- ...your browser only supports Manifest V3 extensions. This is the case for Chrome [^2] , Edge and most Chromium browsers.
|
||||
- ...your browser only supports Manifest V3 extensions. This is the case for Chrome[^2].
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@@ -119,6 +120,6 @@ Additional filter lists do slow things down and may increase your attack surface
|
||||
|
||||
[^1]: uBlock Origin Lite *itself* will consume no resources, because it uses newer APIs which make the browser process the filter lists natively, instead of running JavaScript code within the extension to handle the filtering. However, this resource advantage is only [theoretical](https://github.com/uBlockOrigin/uBOL-home/wiki/Frequently-asked-questions-(FAQ)#is-ubol-more-efficient-cpu--and-memory-wise-than-ubo), because it's possible that standard uBlock Origin's filtering code is more efficient than your browser's native filtering code. This has not yet been benchmarked.
|
||||
|
||||
[^2]: A [workaround](https://github.com/uBlockOrigin/uBlock-issues/discussions/3690#discussioncomment-14548779) stil exists as of early December 2025.
|
||||
[^2]: [Brave](https://brave.com/blog/brave-shields-manifest-v3/) and [Opera](https://xcancel.com/Opera_Security/status/2066543496001888753) have committed to maintain MV2 support for as long as they're able to.
|
||||
|
||||
[^3]: This is starting to change, as MV3 extensions can now request to use scripts. This has enabled [AdGuard](https://adguard.com/en/blog/adguard-browser-extension-v5-2.html) to propose to import custom filters list by the url, as opposed to having to manually paste the rules, as is the case with uBOL.
|
||||
|
||||
@@ -27,13 +27,12 @@ The quickest, most effective, and most private way to remove yourself from peopl
|
||||
|
||||
You should search for your information on these sites first, and submit an opt-out request if your information is found. Removing your data from these providers typically removes your data from many smaller sites at the same time.
|
||||
|
||||
- Advanced Background Checks ([Search](https://advancedbackgroundchecks.com), [Opt-Out](https://advancedbackgroundchecks.com/removal))
|
||||
- Advanced Background Checks ([Search](https://advancedbackgroundchecks.com), [Opt-Out](https://www.advancedbackgroundchecks.com/opt-out))
|
||||
- BeenVerified ([Search](https://beenverified.com/app/optout/search), [Opt-Out](https://beenverified.com/app/optout/address-search))
|
||||
- CheckPeople ([Search](https://checkpeople.com/do-not-sell-info), select *Remove Record* to opt-out)
|
||||
- ClustrMaps ([Search](https://clustrmaps.com), [Opt-Out](https://clustrmaps.com/bl/opt-out))
|
||||
- InfoTracer ([Search](https://infotracer.com), [Opt-Out](https://infotracer.com/optout))
|
||||
- Intelius ([Search](https://intelius.com), [Opt-Out](https://suppression.peopleconnect.us/login))
|
||||
- PeekYou ([Search](https://peekyou.com), [Opt-Out](https://peekyou.com/about/contact/ccpa_optout/do_not_sell))
|
||||
- PublicDataUSA ([Search](https://publicdatausa.com), [Opt-Out](https://publicdatausa.com/remove.php))
|
||||
- Radaris ([Search](https://radaris.com), [Opt-Out](https://radaris.com/page/how-to-remove))
|
||||
- Spokeo ([Search](https://spokeo.com/search), [Opt-Out](https://spokeo.com/optout))
|
||||
@@ -83,7 +82,6 @@ Our [testing](https://www.privacyguides.org/articles/2025/02/03/easyoptouts-revi
|
||||
EasyOptOuts does not cover the following sites we consider to be "high priority," so you should still manually opt-out of:
|
||||
|
||||
- Intelius ([Search](https://intelius.com), [Opt-Out](https://suppression.peopleconnect.us/login))
|
||||
- PeekYou ([Search](https://peekyou.com), [Opt-Out](https://peekyou.com/about/contact/ccpa_optout/do_not_sell))
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
@@ -197,12 +197,6 @@ Additionally, the Mozilla Accounts service collects [some technical data](https:
|
||||
1. Open your [profile settings on accounts.firefox.com](https://accounts.firefox.com/settings#data-collection)
|
||||
2. Uncheck **Data Collection and Use** > **Help improve Firefox Accounts**
|
||||
|
||||
##### Website Advertising Preferences
|
||||
|
||||
- [ ] Uncheck **Allow websites to perform privacy-preserving ad measurement**
|
||||
|
||||
With the release of Firefox 128, a new setting for [privacy-preserving attribution](https://support.mozilla.org/kb/privacy-preserving-attribution) (PPA) has been added and [enabled by default](https://blog.privacyguides.org/2024/07/14/mozilla-disappoints-us-yet-again-2). PPA allows advertisers to use your web browser to measure the effectiveness of web campaigns, instead of using traditional JavaScript-based tracking. We consider this behavior to be outside the scope of a user agent's responsibilities, and the fact that it is disabled by default in Arkenfox is an additional indicator for disabling this feature.
|
||||
|
||||
##### HTTPS-Only Mode
|
||||
|
||||
- [x] Select **Enable HTTPS-Only Mode in all windows**
|
||||
|
||||
+2
-2
@@ -8,7 +8,7 @@ cover: desktop.webp
|
||||
|
||||
- [:material-account-cash: Surveillance Capitalism](basics/common-threats.md#surveillance-as-a-business-model){ .pg-brown }
|
||||
|
||||
Linux distributions are commonly recommended for privacy protection and software freedom. If you don't already use Linux, below are some distributions we suggest trying out, as well as some general privacy and security improvement tips that are applicable to many Linux distributions.
|
||||
Linux distributions are commonly recommended for privacy protection and software freedom. If you don't already use Linux, below are some distributions we suggest trying out, as well as some general privacy and security improvement tips that are applicable to many Linux distributions. Please note that some of our recommended software may not be packaged for your Linux distribution of choice.
|
||||
|
||||
- [General Linux Overview :material-arrow-right-drop-circle:](os/linux-overview.md)
|
||||
|
||||
@@ -126,7 +126,7 @@ NixOS is an independent distribution based on the Nix package manager with a foc
|
||||
|
||||
NixOS’s package manager keeps every version of every package in a different folder in the **Nix store**. Due to this you can have different versions of the same package installed on your system. After the package contents have been written to the folder, the folder is made read-only.
|
||||
|
||||
NixOS also provides atomic updates. It first downloads (or builds) the packages and files for the new system generation and then switches to it. There are different ways to switch to a new generation: you can tell NixOS to activate it after reboot, or you can switch to it at runtime. You can also *test* the new generation by switching to it at runtime, but not setting it as the current system generation. If something in the update process breaks, you can just reboot and automatically and return to a working version of your system.
|
||||
NixOS also provides atomic updates. It first downloads (or builds) the packages and files for the new system generation and then switches to it. There are different ways to switch to a new generation: you can tell NixOS to activate it after reboot, or you can switch to it at runtime. You can also *test* the new generation by switching to it at runtime, but not setting it as the current system generation. If something breaks during the update process, you can just reboot to return to a working version of your system.
|
||||
|
||||
The Nix package manager uses a purely functional language—which is also called Nix—to define packages.
|
||||
|
||||
|
||||
@@ -77,7 +77,7 @@ These options can be found in :material-menu: → **Settings** → **Privacy & S
|
||||
|
||||
##### Telemetry
|
||||
|
||||
- [ ] Uncheck **Allow Thunderbird to send technical and interaction data to Mozilla**
|
||||
- [ ] Uncheck **Allow Thunderbird to send technical and interaction data to Mozilla**
|
||||
|
||||
#### Thunderbird-user.js (advanced)
|
||||
|
||||
|
||||
+2
-2
@@ -158,7 +158,7 @@ Accounts start with up to 2 GB storage, which can be upgraded as needed.
|
||||
</div>
|
||||
|
||||
#### :material-check:{ .pg-green } Custom Domains and Aliases
|
||||
z
|
||||
|
||||
Mailbox Mail lets you use your own domain, and they support [catch-all](https://kb.mailbox.org/en/private/custom-domains/use-your-own-domain-with-catch-all/) addresses. Mailbox Mail also supports [sub-addressing](https://kb.mailbox.org/en/private/e-mail/what-is-an-alias-and-how-do-i-use-it/), which is useful if you don't want to purchase a domain.
|
||||
|
||||
#### :material-check:{ .pg-green } Private Payment Methods
|
||||
@@ -167,7 +167,7 @@ Mailbox Mail doesn't accept any cryptocurrencies as a result of their payment pr
|
||||
|
||||
#### :material-check:{ .pg-green } Account Security
|
||||
|
||||
Mailbox Mail supports [two-factor authentication](https://kb.mailbox.org/en/private/security-and-privacy/how-to-use-two-factor-authentication-2fa/) for their webmail only. You can use either TOTP or a [YubiKey](security-keys.md#yubikey) via the [YubiCloud](https://yubico.com/products/services-software/yubicloud). Web standards such as [WebAuthn](basics/multi-factor-authentication.md#fido-fast-identity-online) are not yet supported.
|
||||
Mailbox Mail supports [two-factor authentication](https://kb.mailbox.org/en/private/security-and-privacy/how-to-use-two-factor-authentication-2fa/) for their webmail only. You can use either TOTP or a [YubiKey](security-keys.md#yubikey-5) via the [YubiCloud](https://yubico.com/products/services-software/yubicloud). Web standards such as [WebAuthn](basics/multi-factor-authentication.md#fido-fast-identity-online) are not yet supported.
|
||||
|
||||
#### :material-information-outline:{ .pg-blue } Data Security
|
||||
|
||||
|
||||
@@ -0,0 +1,79 @@
|
||||
---
|
||||
title: Hardware Wallets
|
||||
icon: material/cash-lock
|
||||
description: Cryptocurrency hardware wallets secure your private keys against adversaries.
|
||||
cover: hardware-wallets.webp
|
||||
---
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
- [:material-target-account: Targeted Attacks](basics/common-threats.md#attacks-against-specific-individuals){ .pg-red }
|
||||
- [:material-bug-outline: Passive Attacks](basics/common-threats.md#security-and-privacy){ .pg-orange }
|
||||
|
||||
A cryptocurrency **hardware wallet** is a dedicated physical device that stores the private keys used to access and authorize transactions from your cryptocurrency accounts. Unlike a software wallet on a phone or computer, it keeps those keys isolated from internet-connected devices, reducing the risk that malware, phishing, or a compromised operating system can steal them.
|
||||
|
||||
## Recommendations
|
||||
|
||||
Our top recommendations are full-featured products from the companies we list here, and support all major operating systems (notably including iOS).
|
||||
|
||||
### Ledger Nano Gen 5
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Ledger Nano Gen 5** hardware wallet places the private keys, wallet operating system, and cryptocurrency applications inside a certified secure element. Unlike Trezor's devices, it is also a recommended [security key](security-keys.md#ledger) product.
|
||||
|
||||
</div>
|
||||
|
||||
Ledger runs its *entire* operating system and stores your private keys inside its CC EAL6+ certified secure element. This is a simpler configuration than [Trezor](#trezor-safe-7)'s multi-chip design (described in the next section), but that doesn't necessarily translate to greater or lesser security. In theory, it may provide a smaller attack surface and offer more resistance to offline attacks or some very sophisticated attacks against a running device, but that comes at the cost of Trezor's greater transparency.
|
||||
|
||||
Wallet apps installed on Ledger devices are [open-source](https://support.ledger.com/article/11132311094813-zd), as is the companion Ledger Wallet software you install on your computer. However, the Ledger OS/firmware and the secure element implementation are proprietary.
|
||||
|
||||
The **Ledger Flex** and **Ledger Stax** are near-identical devices you could also consider. There are no security or software functionality differences between all three of these devices. The Flex and Stax devices have increasingly larger, higher resolution displays; more premium materials; and the Stax has wireless Qi charging.
|
||||
|
||||
### Trezor Safe 7
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Trezor Safe 7** is a modern touchscreen hardware wallet notable for using a dual secure element approach to security. It connects via USB-C or with Bluetooth.
|
||||
|
||||
</div>
|
||||
|
||||
The Safe 7 uses an industry-standard CC EAL6 secure element alongside an open architecture [TROPIC01](https://tropicsquare.com/tropic01) secure element to provide security. It also uses a general-purpose microcontroller unit (MCU), which is not a secure element but allows for better inspectability for developers and researchers.
|
||||
|
||||
In this setup, your seed is not stored in either secure element, it is stored *encrypted* in the general-purpose MCU. However, decrypting it requires key material stored by both secure elements. Trezor claims an attacker would need to compromise all three layers to recover the encrypted hardware data. Thus, Trezor's approach balances open-source and transparency in their MCU firmware and the less proven but more open TROPIC01 chip, alongside the more proven CC EAL6+ secure element from a commercial provider.
|
||||
|
||||
Trezor devices are not [recommended FIDO2 security keys](security-keys.md), although they do have security key functionality, because Trezor has not sought out certification from the FIDO Alliance to validate their security key software is implemented properly. Some websites/apps will require a key to have some level of FIDO certification, so you may experience compatibility issues using this device for that purpose.
|
||||
|
||||
## Budget Picks
|
||||
|
||||
Our budget recommendations are generally just as secure as our top recommendations, but neither support iOS. They also have more limited, button-based interfaces instead of touchscreens, making them well-suited for long-term storage, but more inconvenient for frequent use.
|
||||
|
||||
### Trezor Safe 3
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Trezor Safe 3** is a simple and inexpensive USB-C only hardware wallet. Like the [Safe 7](#trezor-safe-7), it has open-source firmware and supporting software so that it can be independently inspected.
|
||||
|
||||
</div>
|
||||
|
||||
The **Trezor Safe 5** is a near-identical device you could also consider. There are no security or software functionality differences between the Safe 3 and Safe 5. However, the Safe 5 has a larger touchscreen for easier navigation, instead of the Safe 3's smaller display and two-button navigation.
|
||||
|
||||
The Safe 3/5 devices do **not** use the same dual secure enclave configuration as the Safe 7. Instead, they omit the TROPIC01 to run a single EAL CC6+ secure element, which stores material to unlock the private keys that are stored encrypted on the separate general-purpose MCU.
|
||||
|
||||
### Ledger Nano S Plus
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
The **Ledger Nano S Plus** is a small hardware wallet with a two-button interface, recommended by Ledger as a "backup signer" rather than a regular-use device. Compared to the [Nano Gen 5](#ledger-nano-gen-5) it only has USB connectivity, and it has no internal battery, which may provide an improvement in longevity.
|
||||
|
||||
</div>
|
||||
|
||||
The Nano S Plus lacks NFC connectivity, making it less suitable for [security key](security-keys.md#ledger) functionality on mobile devices, and making it incompatible with Ledger's Recovery Key backup solution. All four Ledger devices we recommend have essentially the same security properties, they only differ in interfaces.
|
||||
|
||||
Note we do **not** recommend the similar Ledger Nano X still in production. The Nano X uses an older secure element which is only CC EAL5 certified, while our minimum criteria requires EAL6. There are limited uses for the Nano X compared to all other devices Ledger offers, so it generally does not make sense as a new purchase.
|
||||
|
||||
## Criteria
|
||||
|
||||
**Please note we are not affiliated with any of the projects we recommend.** In addition to [our standard criteria](about/criteria.md), we have developed a clear set of requirements to allow us to provide objective recommendations. We suggest you familiarize yourself with this list before choosing to use a project, and conduct your own research to ensure it's the right choice for you.
|
||||
|
||||
- Must use a secure element which meets Common Criteria EAL6 or higher.
|
||||
- Must support a [recommended cryptocurrency](cryptocurrency.md).
|
||||
+23
-21
@@ -77,11 +77,11 @@ Tor Browser is the only way to truly browse the internet anonymously. When you u
|
||||
|
||||
=== "Android"
|
||||
|
||||
These options can be found in :material-menu: → **Settings** → **Brave Shields & privacy**.
|
||||
These options can be found in :material-dots-vertical: → **Settings** → **Brave Shields & privacy**.
|
||||
|
||||
=== "iOS"
|
||||
|
||||
These options can be found in :fontawesome-solid-ellipsis: → **Settings** → **Shields & Privacy**.
|
||||
These options can be found in :material-dots-horizontal: → **All Settings** → **Shields & Privacy**.
|
||||
|
||||
#### Brave shields global defaults
|
||||
|
||||
@@ -109,7 +109,7 @@ Shields' options can be downgraded on a per-site basis as needed, but by default
|
||||
|
||||
</details>
|
||||
|
||||
- [x] Select **Forget me when I close this site**
|
||||
- [x] Select **Site Tabs Closed** under *Auto Shred*
|
||||
|
||||
</div>
|
||||
|
||||
@@ -138,24 +138,16 @@ Shields' options can be downgraded on a per-site basis as needed, but by default
|
||||
|
||||
1. This option disables JavaScript, which will break a lot of sites. To unbreak them, you can set exceptions on a per-site basis by tapping on the Shield icon in the address bar and unchecking this setting under *Advanced controls*.
|
||||
|
||||
##### Clear browsing data (Android only)
|
||||
|
||||
- [x] Select **Clear data on exit**
|
||||
|
||||
##### Social Media Blocking (Android only)
|
||||
|
||||
- [ ] Uncheck all social media components
|
||||
|
||||
#### Other privacy settings
|
||||
|
||||
=== "Android"
|
||||
|
||||
<div class="annotate" markdown>
|
||||
|
||||
- [x] Select **Disable non-proxied UDP** under [*WebRTC IP handling policy*](https://support.brave.com/hc/articles/360017989132-How-do-I-change-my-Privacy-Settings#webrtc)
|
||||
- [x] (Optional) Select **No protection** under *Safe Browsing* (1)
|
||||
- [x] Select **Disable non-proxied UDP** under [*WebRTC IP handling policy*](https://support.brave.com/hc/articles/360017989132-How-do-I-change-my-Privacy-Settings#webrtc)
|
||||
- [ ] Uncheck **Allow sites to check if you have payment methods saved**
|
||||
- [ ] Uncheck **Javascript optimization & security** under the setting with the same name
|
||||
- [x] Select **Do not speed up sites with Brave's V8 engine but make Brave slightly more resistant to attacks**
|
||||
- [x] Select **Close tabs on exit**
|
||||
- [ ] Uncheck **Allow privacy-preserving product analytics (P3A)**
|
||||
- [ ] Uncheck **Automatically send diagnostic reports**
|
||||
@@ -170,23 +162,33 @@ Shields' options can be downgraded on a per-site basis as needed, but by default
|
||||
- [ ] Uncheck **Allow Privacy-Preserving Product Analytics (P3A)**
|
||||
- [ ] Uncheck **Automatically send daily usage ping to Brave**
|
||||
|
||||
#### Leo
|
||||
#### Leo AI
|
||||
|
||||
These options can be found in :material-menu: → **Settings** → **Leo**.
|
||||
=== "Android"
|
||||
|
||||
<div class="annotate" markdown>
|
||||
These options can be found in :material-dots-vertical: → **Settings** → **Leo AI**.
|
||||
|
||||
- [ ] Uncheck **Show autocomplete suggestions in address bar** (1)
|
||||
- [ ] Uncheck **Show autocomplete suggestions in address bar**
|
||||
|
||||
</div>
|
||||
=== "iOS"
|
||||
|
||||
1. This option is not present in Brave's iOS app.
|
||||
These options can be found in :material-dots-horizontal: → **All Settings** → **Leo AI**.
|
||||
|
||||
- [ ] Uncheck **Show In Quick Search Engine Bar**
|
||||
|
||||
#### Search engines
|
||||
|
||||
These options can be found in :material-menu:/:fontawesome-solid-ellipsis: → **Settings** → **Search engines**.
|
||||
=== "Android"
|
||||
|
||||
- [ ] Uncheck **Show search suggestions**
|
||||
These options can be found in :material-dots-vertical: → **Settings** → **Search engines**.
|
||||
|
||||
- [ ] Uncheck **Show search suggestions**
|
||||
|
||||
=== "iOS"
|
||||
|
||||
These options can be found in :material-dots-horizontal: → **All Settings** → **Search engines**.
|
||||
|
||||
- [ ] Uncheck **Show In Quick Search Engine Bar**
|
||||
|
||||
#### Brave Sync
|
||||
|
||||
|
||||
@@ -94,7 +94,7 @@ SELinux on [Fedora](https://docs.fedoraproject.org/en-US/quick-docs/selinux-gett
|
||||
|
||||
Most Linux distributions have an option within its installer for enabling [LUKS](../encryption.md#linux-unified-key-setup) FDE. If this option isn’t set at installation time, you will have to back up your data and re-install, as encryption is applied after [disk partitioning](https://en.wikipedia.org/wiki/Disk_partitioning), but before [file systems](https://en.wikipedia.org/wiki/File_system) are formatted. We also suggest securely erasing your storage device:
|
||||
|
||||
- [Secure Data Erasure :material-arrow-right-drop-circle:](https://blog.privacyguides.org/2022/05/25/secure-data-erasure)
|
||||
- [Secure Data Erasure :material-arrow-right-drop-circle:](https://www.privacyguides.org/articles/2022/05/25/secure-data-erasure/)
|
||||
|
||||
### Swap
|
||||
|
||||
|
||||
@@ -127,17 +127,6 @@ This last setting disables OneDrive on your system; make sure to change it to **
|
||||
|
||||
- Improve inking and typing recognition: **Disabled**
|
||||
|
||||
#### Windows AI
|
||||
|
||||
<div class="admonition info" markdown>
|
||||
<p class="admonition-title">Windows Recall</p>
|
||||
|
||||
Windows 11 recently introduced a feature called **Recall**, which records all your activity and creates a searchable archive of that activity history. This is a massive privacy vulnerability, because those archives can potentially store highly sensitive information (essentially anything displayed on your screen), and can be trivially accessed by local administrators or malicious actors with user-level access to your device.
|
||||
|
||||
</div>
|
||||
|
||||
- Turn off saving snapshots of Windows: **Enabled**
|
||||
|
||||
#### Windows Error Reporting
|
||||
|
||||
- Do not send additional data: **Enabled**
|
||||
|
||||
@@ -26,7 +26,7 @@ This section is a work in progress, because it takes considerably more time and
|
||||
|
||||
## Privacy Notes
|
||||
|
||||
Microsoft Windows, particularly those versions aimed at consumers like the **Home** version often don't prioritize privacy-friendly features by [default](https://theguardian.com/technology/2015/jul/31/windows-10-microsoft-faces-criticism-over-privacy-default-settings). As a result we often see more [data collection](https://en.wikipedia.org/wiki/Criticism_of_Microsoft#Telemetry_and_data_collection) than necessary, without any real warnings that this is the default behavior. In an attempt to compete with Google in the advertising space, [Cortana](https://en.wikipedia.org/wiki/Cortana_(virtual_assistant)) has included unique identifiers such as an "advertising ID" in order to correlate usage and assist advertisers in targeted advertising. At launch, telemetry could not be disabled in non-enterprise editions of Windows 10. It still cannot be disabled, but Microsoft added the ability to [reduce](https://extremetech.com/computing/243079-upcoming-windows-update-reduces-spying-microsoft-still-mum-data-collects) the data that is sent to them.
|
||||
Microsoft Windows, particularly those versions aimed at consumers like the **Home** version often don't prioritize privacy-friendly features by [default](https://theguardian.com/technology/2015/jul/31/windows-10-microsoft-faces-criticism-over-privacy-default-settings). As a result we often see more [data collection](https://en.wikipedia.org/wiki/Criticism_of_Microsoft#Telemetry_and_data_collection) than necessary, without any real warnings that this is the default behavior. In an attempt to compete with Google in the advertising space, [Cortana](https://en.wikipedia.org/wiki/Cortana_(virtual_assistant)) has included unique identifiers such as an "advertising ID" in order to correlate usage and assist advertisers in targeted advertising. At launch, telemetry could not be disabled in non-enterprise editions of Windows 10. It still cannot be disabled, but Microsoft added the ability to [reduce](https://extremetech.com/computing/243079-upcoming-windows-update-reduces-spying-microsoft-still-mum-data-collects) the data that is sent to them.
|
||||
|
||||
With Windows 11 there are a number of restrictions or defaults such as:
|
||||
|
||||
|
||||
@@ -67,7 +67,7 @@ The protocol was independently [audited](https://eprint.iacr.org/2016/1013.pdf)
|
||||
|
||||
### Molly (Android)
|
||||
|
||||
If you use Android and your threat model requires protecting against [:material-target-account: Targeted Attacks](basics/common-threats.md#attacks-against-specific-individuals){ .pg-red } you may consider using this alternative app, which features a number of security and usability improvements, to access the Signal network.
|
||||
If you use Android and your threat model requires protecting against [:material-target-account: Targeted Attacks](basics/common-threats.md#attacks-against-specific-individuals){ .pg-red } you may consider using this alternative app, which features a number of security and usability improvements, to access the Signal network.
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
|
||||
+41
-35
@@ -11,6 +11,16 @@ cover: multi-factor-authentication.webp
|
||||
|
||||
A physical **security key** adds a very strong layer of protection to your online accounts. Compared to [authenticator apps](multi-factor-authentication.md), the [FIDO2](basics/multi-factor-authentication.md#fido-fast-identity-online) security key protocol is immune to phishing, and cannot be compromised without physical possession of the key itself. Many services support FIDO2/WebAuthn as a multifactor authentication option for securing your account, and some services allow you to use a security key as a strong single-factor authenticator with passwordless authentication.
|
||||
|
||||
| Product | Price | Connector | Authentication | Android | iOS | Firmware Updates | Backup/Sync | Apps | FIDO Certification
|
||||
|:-:|:-:|:-:|:-:|:-:|:-:|:-:|:-:|:-:|:-:
|
||||
| [**Yubico Security Key**](#yubico-security-key) | $29 USD | NFC + USB-C, USB-A Options | Push Button Only, PIN Optional | NFC, USB | NFC, USB | No[^2] | No | FIDO2 | Level 2
|
||||
| **YubiKey Bio - FIDO Edition** | $98 USD | USB-C, USB-A Options | Biometric, PIN Fallback | USB Only | USB Only | No[^2] | No | FIDO2 | Level 2
|
||||
| **[YubiKey 5](#yubikey) NFC** | $58 USD | NFC + USB-C, USB-A Options | Push Button Only, PIN Optional | NFC, USB | NFC, USB | No[^2] | No | FIDO2, OpenPGP, PIV | Level 2
|
||||
| **YubiKey 5 Nano** | $68 USD | USB-C, USB-A Options | Push Button Only, PIN Optional | USB Only | USB Only | No[^2] | No | FIDO2, OpenPGP, PIV | Level 2
|
||||
| **[Ledger](#ledger) Nano S Plus** | $59 USD | USB-C Cable | 4-8 Digit PIN | USB Only | **No** | Yes | Both | FIDO2, OpenPGP, [Cryptocurrency](hardware-wallets.md) | Level 1
|
||||
| **Ledger Nano Gen5, Flex, Stax** | $179 - $399 USD | NFC + USB-C Cable | 4-8 Digit PIN | NFC, USB | NFC Only | Yes | Both | FIDO2, OpenPGP, [Cryptocurrency](hardware-wallets.md) | Level 1
|
||||
| [**Google Titan Key**](#google-titan-security-key) | $30 - $35 USD | NFC + USB-C, USB-A Options | Push Button Only, PIN Optional | NFC, USB | NFC, USB | No | No | FIDO2 | Level 1
|
||||
|
||||
## Yubico Security Key
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
@@ -29,24 +39,15 @@ The **Yubico Security Key** series is the most cost-effective hardware security
|
||||
|
||||
</div>
|
||||
|
||||
These keys are available in both USB-C and USB-A variants, and both options support NFC for use with a mobile device as well.
|
||||
Note that despite the name, the [YubiKey **Bio**](https://www.yubico.com/product/yubikey-bio-series/yubikey-c-bio/) series has a limited feature-set nearly identical to the Yubico Security Key series, rather than the full-fledged [YubiKey](#yubikey) series detailed in the next section. It is another option you could consider if you value biometric authentication.
|
||||
|
||||
This key provides only basic FIDO2 functionality, but for most people that is all you will need. Some notable features the Security Key series does **not** have include:
|
||||
Yubico's basic security keys provide only FIDO2 functionality, but for most people that is all you will need. Some notable features the Security Key series does **not** have include:
|
||||
|
||||
- [Yubico Authenticator](https://yubico.com/products/yubico-authenticator)
|
||||
- CCID Smart Card support (PIV-compatible)
|
||||
- OpenPGP
|
||||
|
||||
If you need any of those features, you should consider their higher-end [YubiKey](#yubikey) series instead.
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">Warning</p>
|
||||
|
||||
The firmware of Yubico's Security Keys is not updatable. If you want features in newer firmware versions, or if there is a vulnerability in the firmware version you are using, you would need to purchase a new key.
|
||||
|
||||
</div>
|
||||
|
||||
## YubiKey
|
||||
## YubiKey 5
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
@@ -64,7 +65,7 @@ The **YubiKey** series from Yubico are among the most popular security keys with
|
||||
|
||||
</div>
|
||||
|
||||
The [comparison table](https://yubico.com/store/compare) shows how the YubiKeys compare to each other and to Yubico's [Security Key](#yubico-security-key) series in terms of features and other specifications. One of the benefits of the YubiKey series is that one key can do almost everything you could expect from a hardware security key. We encourage you to take their [quiz](https://yubico.com/quiz) before purchasing in order to make sure you choose the right security key.
|
||||
This detailed [comparison table](https://yubico.com/store/compare) has more details about how the YubiKeys compare to each other and to Yubico's [Security Key](#yubico-security-key) series in terms of features and other specifications. One of the benefits of the YubiKey series is that one key can do almost everything you could expect from a hardware security key. We encourage you to take their [quiz](https://yubico.com/quiz) before purchasing in order to make sure you choose the right security key.
|
||||
|
||||
YubiKeys can be programmed using the [YubiKey Manager](https://yubico.com/support/download/yubikey-manager) or [YubiKey Personalization Tools](https://yubico.com/support/download/yubikey-personalization-tools). For managing TOTP codes, you can use the [Yubico Authenticator](https://yubico.com/products/yubico-authenticator). All of Yubico's clients are open source.
|
||||
|
||||
@@ -77,32 +78,39 @@ The firmware of YubiKey is not updatable. If you want features in newer firmware
|
||||
|
||||
</div>
|
||||
|
||||
## Nitrokey
|
||||
## Ledger
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
<figure markdown="span">
|
||||
{ width="300" }
|
||||
</figure>
|
||||
|
||||
**Nitrokey** has a cost-effective security key capable of FIDO2/WebAuthn and FIDO U2F called the **Nitrokey Passkey**. For support for features such as PIV, OpenPGP, and TOTP and HOTP authentication, you need to purchase one of their other keys like the **Nitrokey 3**. Currently, only the **Nitrokey 3A Mini** has [FIDO Level 1 Certification](https://nitrokey.com/news/2024/nitrokey-3a-mini-receives-official-fido2-certification).
|
||||
|
||||
[:octicons-home-16: Homepage](https://nitrokey.com){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://nitrokey.com/data-privacy-policy){ .card-link title="Privacy Policy" }
|
||||
[:octicons-info-16:](https://docs.nitrokey.com){ .card-link title="Documentation" }
|
||||
|
||||
</details>
|
||||
**Ledger** makes a number of [cryptocurrency hardware wallet](hardware-wallets.md) products and an optional, FIDO certified [Security Key](https://support.ledger.com/article/12350325732893-zd) app for those wallets which enables FIDO2 security key functionality. If you need a cryptocurrency wallet anyway, this could be an option to consider for security key functionality as well.
|
||||
|
||||
</div>
|
||||
|
||||
The [comparison table](https://nitrokey.com/products/nitrokeys#:~:text=The%20Nitrokey%20Family) shows how the different Nitrokey models compare to each other in terms of features and other specifications. Refer to Nitrokey's [documentation](https://docs.nitrokey.com/nitrokeys/features) for more details about the features available on your Nitrokey.
|
||||
Even if you don't need a cryptocurrency wallet, using Ledger devices as security keys has three key advantages over YubiKey you may wish to consider:
|
||||
|
||||
Nitrokey models can be configured using the [Nitrokey app](https://nitrokey.com/download).
|
||||
1. **Secure PIN authentication.**
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">Warning</p>
|
||||
A 4-8 digit PIN is always required to operate Ledger devices. Additionally, that PIN is entered via the display on the device itself. YubiKey PIN authentication, in contrast, is a software prompt where you enter your PIN on the computer/phone you're using.
|
||||
|
||||
Excluding the Nitrokey 3, Nitrokeys which support HOTP and TOTP do not have encrypted storage, making them vulnerable to physical attacks.
|
||||
2. **Firmware updates.**
|
||||
|
||||
Both the operating system firmware and the Security Key app software can be updated via the Ledger Wallet app if new security improvements are released.
|
||||
|
||||
3. **Backups and sync.**
|
||||
|
||||
When setting up your Ledger device you will create a 24-word "seed phrase." Your security key credentials are tied to this seed phrase, meaning that if you lose/break your Ledger device, you can use the same 24-word phrase to set up a new Ledger device, and it will work with your existing accounts.
|
||||
|
||||
You can also use the same 24-word phrase to set up multiple Ledger devices simultaneously, and all of them will work with your accounts in a "synced" fashion, instead of needing to register each security key individually.
|
||||
|
||||
Some may consider the last two features to be downsides. Firmware updates can add additional attack surface and introduce new bugs at a later time. However, it is worth noting that many non-updatable security keys from various vendors have been recalled due to discovered security flaws which could not be patched. Backups can also be dangerous if your seed phrase is not properly secured, because it could be used by an attacker to create a duplicate security key if it is leaked.
|
||||
|
||||
Note that while all of Ledger's current products technically meet our criteria *for security keys*, the Ledger Nano X does **not** meet our separate [criteria for hardware wallets](hardware-wallets.md#criteria) because it uses an older secure element not certified to the same level as their other products. The Ledger Nano X has no advantages over any of their other devices for security key purposes, so we would not recommend purchasing one.
|
||||
|
||||
## Google Titan Security Key
|
||||
|
||||
<div class="admonition recommendation" markdown>
|
||||
|
||||
Google Titan Security Keys are Yubico-manufactured FIDO2 USB/NFC keys very similar to the [Yubico Security Key](#yubico-security-key) lineup. However, Titan security keys use a different secure element than Yubico's, and they run firmware created by Google. There are generally no functional differences between the two options.
|
||||
|
||||
</div>
|
||||
|
||||
@@ -113,17 +121,15 @@ Excluding the Nitrokey 3, Nitrokeys which support HOTP and TOTP do not have encr
|
||||
### Minimum Requirements
|
||||
|
||||
- Must use high-quality, tamper-resistant hardware security modules.
|
||||
- Must support the latest FIDO2 specification.
|
||||
- Must not allow private key extraction.
|
||||
- Devices which cost over $35 must support handling OpenPGP and S/MIME.
|
||||
- Must be [certified](https://fidoalliance.org/certification/fido-certified-products/) by FIDO Alliance for the FIDO2 specification.
|
||||
- Must have USB-C and NFC connectivity options in product line.
|
||||
|
||||
### Best-Case
|
||||
|
||||
Our best-case criteria represents what we would like to see from the perfect project in this category. Our recommendations may not include any or all of this functionality, but those which do may rank higher than others on this page.
|
||||
|
||||
- Should be available in USB-C form factor.
|
||||
- Should be available with NFC.
|
||||
- Should support TOTP secret storage.
|
||||
- Should support secure firmware updates.
|
||||
|
||||
[^1]: Some governments or other organizations may require a key with Level 2 certification, but most people do not have to worry about this distinction.
|
||||
[^2]: The firmware of Yubico's Security Keys is not updatable. If you want features in newer firmware versions, or if there is a vulnerability in the firmware version you are using, you would need to purchase a new key.
|
||||
|
||||
+12
-2
@@ -603,13 +603,23 @@ For encrypting your OS drive, we typically recommend using the encryption tool y
|
||||
|
||||
## Hardware
|
||||
|
||||
### Hardware Wallets
|
||||
|
||||
<div class="grid cards" markdown>
|
||||
|
||||
- [Ledger](hardware-wallets.md#ledger-nano-gen-5)
|
||||
- [Trezor](hardware-wallets.md#trezor-safe-7)
|
||||
|
||||
</div>
|
||||
|
||||
### Security Keys
|
||||
|
||||
<div class="grid cards" markdown>
|
||||
|
||||
- { .twemoji loading=lazy } [Yubico Security Key](security-keys.md#yubico-security-key)
|
||||
- { .twemoji loading=lazy } [YubiKey](security-keys.md#yubikey)
|
||||
- { .twemoji loading=lazy } [Nitrokey](security-keys.md#nitrokey)
|
||||
- { .twemoji loading=lazy } [YubiKey](security-keys.md#yubikey-5)
|
||||
- [Ledger](security-keys.md#ledger)
|
||||
- [Google Titan Security Key](security-keys.md#google-titan-security-key)
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
+167
-140
@@ -18,25 +18,25 @@
|
||||
# FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
# IN THE SOFTWARE.
|
||||
|
||||
docs_dir: !ENV [ BUILD_DOCS_DIR, "docs" ]
|
||||
site_url: !ENV [ BUILD_SITE_URL, "https://www.privacyguides.org/en/" ]
|
||||
site_dir: !ENV [ BUILD_SITE_DIR, "site/en" ]
|
||||
docs_dir: !ENV [BUILD_DOCS_DIR, "docs"]
|
||||
site_url: !ENV [BUILD_SITE_URL, "https://www.privacyguides.org/en/"]
|
||||
site_dir: !ENV [BUILD_SITE_DIR, "site/en"]
|
||||
|
||||
site_name: Privacy Guides
|
||||
site_description:
|
||||
!ENV [
|
||||
site_description: !ENV [
|
||||
SITE_DESCRIPTION,
|
||||
"Privacy Guides is your central privacy and security resource to protect
|
||||
yourself online.",
|
||||
yourself online.",
|
||||
]
|
||||
edit_uri_template: !ENV [ BUILD_EDIT_URI_TEMPLATE, "blob/main/docs/{path}?plain=1" ]
|
||||
edit_uri_template:
|
||||
!ENV [BUILD_EDIT_URI_TEMPLATE, "blob/main/docs/{path}?plain=1"]
|
||||
|
||||
extra:
|
||||
scope: /
|
||||
homepage: /
|
||||
generator: false
|
||||
context: !ENV [ BUILD_CONTEXT, "production" ]
|
||||
offline: !ENV [ BUILD_OFFLINE, false ]
|
||||
context: !ENV [BUILD_CONTEXT, "production"]
|
||||
offline: !ENV [BUILD_OFFLINE, false]
|
||||
deploy: !ENV DEPLOY_ID
|
||||
ghost:
|
||||
base_url: https://www.privacyguides.org
|
||||
@@ -45,99 +45,124 @@ extra:
|
||||
content_api_key: da9d77deb3e85ee73925167f3a
|
||||
privacy_guides:
|
||||
footer:
|
||||
intro:
|
||||
!ENV [
|
||||
intro: !ENV [
|
||||
FOOTER_INTRO,
|
||||
"Privacy Guides is a non-profit, socially motivated website that provides
|
||||
information for protecting your data security and privacy.",
|
||||
information for protecting your data security and privacy.",
|
||||
]
|
||||
note:
|
||||
!ENV [
|
||||
note: !ENV [
|
||||
FOOTER_NOTE,
|
||||
"We do not make money from recommending certain products, and we do not use
|
||||
affiliate links.",
|
||||
affiliate links.",
|
||||
]
|
||||
copyright:
|
||||
author: !ENV [ FOOTER_COPYRIGHT_AUTHOR, "Privacy Guides and contributors." ]
|
||||
date: !ENV [ FOOTER_COPYRIGHT_DATE, "2019-2025" ]
|
||||
author:
|
||||
!ENV [FOOTER_COPYRIGHT_AUTHOR, "Privacy Guides and contributors."]
|
||||
date: !ENV [FOOTER_COPYRIGHT_DATE, "2019-2025"]
|
||||
license:
|
||||
- fontawesome/brands/creative-commons
|
||||
- fontawesome/brands/creative-commons-by
|
||||
- fontawesome/brands/creative-commons-sa
|
||||
links:
|
||||
- name: !ENV [ FOOTER_PRIVACY_NOTICE, "Privacy notice." ]
|
||||
- name: !ENV [FOOTER_PRIVACY_NOTICE, "Privacy notice."]
|
||||
url: https://www.privacyguides.org/en/privacy/
|
||||
homepage:
|
||||
description:
|
||||
!ENV [
|
||||
description: !ENV [
|
||||
HOMEPAGE_DESCRIPTION,
|
||||
"A socially motivated website which provides information about protecting
|
||||
your online data privacy and security.",
|
||||
your online data privacy and security.",
|
||||
]
|
||||
hero:
|
||||
header: !ENV [ HOMEPAGE_HEADER, "The guide to restoring your online privacy." ]
|
||||
subheader:
|
||||
!ENV [
|
||||
header:
|
||||
!ENV [HOMEPAGE_HEADER, "The guide to restoring your online privacy."]
|
||||
subheader: !ENV [
|
||||
HOMEPAGE_SUBHEADER,
|
||||
"Massive organizations are monitoring your online activities. Privacy
|
||||
Guides is your central privacy and security resource to protect
|
||||
yourself online.",
|
||||
Guides is your central privacy and security resource to protect
|
||||
yourself online.",
|
||||
]
|
||||
buttons:
|
||||
- name: !ENV [ HOMEPAGE_BUTTON_GET_STARTED_NAME, "Start Your Privacy Journey" ]
|
||||
title: !ENV [ HOMEPAGE_BUTTON_GET_STARTED_TITLE, "The first step of your privacy journey" ]
|
||||
link: !ENV [ HOMEPAGE_BUTTON_GET_STARTED_LINK, "basics/why-privacy-matters/" ]
|
||||
- name:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_GET_STARTED_NAME,
|
||||
"Start Your Privacy Journey",
|
||||
]
|
||||
title:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_GET_STARTED_TITLE,
|
||||
"The first step of your privacy journey",
|
||||
]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_GET_STARTED_LINK,
|
||||
"basics/why-privacy-matters/",
|
||||
]
|
||||
class: md-button md-button--primary
|
||||
- name: !ENV [ HOMEPAGE_BUTTON_TOOLS_NAME, "Recommended Tools" ]
|
||||
- name: !ENV [HOMEPAGE_BUTTON_TOOLS_NAME, "Recommended Tools"]
|
||||
title:
|
||||
!ENV [
|
||||
HOMEPAGE_BUTTON_TOOLS_TITLE,
|
||||
"Recommended privacy tools, services, and knowledge",
|
||||
]
|
||||
link: !ENV [ HOMEPAGE_BUTTON_TOOLS_LINK, "tools/" ]
|
||||
link: !ENV [HOMEPAGE_BUTTON_TOOLS_LINK, "tools/"]
|
||||
class: md-button
|
||||
cta:
|
||||
- title: !ENV [ HOMEPAGE_CTA_TITLE, "We need you! Here's how to get involved:" ]
|
||||
- title:
|
||||
!ENV [
|
||||
HOMEPAGE_CTA_TITLE,
|
||||
"We need you! Here's how to get involved:",
|
||||
]
|
||||
links:
|
||||
- icon: simple/discourse
|
||||
name: !ENV [ HOMEPAGE_CTA_FORUM_NAME, "Join the forum" ]
|
||||
name: !ENV [HOMEPAGE_CTA_FORUM_NAME, "Join the forum"]
|
||||
link: https://discuss.privacyguides.net/
|
||||
- icon: simple/mastodon
|
||||
name: !ENV [ HOMEPAGE_CTA_MASTODON_NAME, "Follow us on Mastodon" ]
|
||||
name: !ENV [HOMEPAGE_CTA_MASTODON_NAME, "Follow us on Mastodon"]
|
||||
link: https://mastodon.neat.computer/@privacyguides
|
||||
- icon: simple/github
|
||||
name: !ENV [ HOMEPAGE_CTA_GITHUB_NAME, "Contribute on GitHub" ]
|
||||
name: !ENV [HOMEPAGE_CTA_GITHUB_NAME, "Contribute on GitHub"]
|
||||
link: https://github.com/privacyguides/privacyguides.org
|
||||
- icon: material/translate
|
||||
name: !ENV [ HOMEPAGE_CTA_TRANSLATE_NAME, "Help translate" ]
|
||||
name: !ENV [HOMEPAGE_CTA_TRANSLATE_NAME, "Help translate"]
|
||||
link: https://crowdin.com/project/privacyguides
|
||||
- icon: simple/matrix
|
||||
name: !ENV [ HOMEPAGE_CTA_MATRIX_NAME, "Join the Matrix chat" ]
|
||||
name: !ENV [HOMEPAGE_CTA_MATRIX_NAME, "Join the Matrix chat"]
|
||||
link: https://matrix.to/#/#privacyguides:matrix.org
|
||||
- icon: material/information-outline
|
||||
name: !ENV [ HOMEPAGE_CTA_ABOUT_NAME, "Learn more about us" ]
|
||||
link: !ENV [ HOMEPAGE_CTA_ABOUT_LINK, "about/" ]
|
||||
name: !ENV [HOMEPAGE_CTA_ABOUT_NAME, "Learn more about us"]
|
||||
link: !ENV [HOMEPAGE_CTA_ABOUT_LINK, "about/"]
|
||||
- icon: material/hand-coin
|
||||
name: !ENV [ HOMEPAGE_CTA_DONATE_NAME, "Donate to Privacy Guides" ]
|
||||
link: !ENV [ HOMEPAGE_CTA_DONATE_LINK, "about/donate/" ]
|
||||
description:
|
||||
!ENV [
|
||||
name: !ENV [HOMEPAGE_CTA_DONATE_NAME, "Donate to Privacy Guides"]
|
||||
link: !ENV [HOMEPAGE_CTA_DONATE_LINK, "about/donate/"]
|
||||
description: !ENV [
|
||||
HOMEPAGE_CTA_DESCRIPTION,
|
||||
"If you spot an error, think a provider should not be listed, notice a
|
||||
qualified provider is missing, believe a browser plugin is no
|
||||
longer the best choice, or uncover any other issue, please let
|
||||
us know.",
|
||||
qualified provider is missing, believe a browser plugin is no
|
||||
longer the best choice, or uncover any other issue, please let
|
||||
us know.",
|
||||
]
|
||||
rss:
|
||||
- title: !ENV [ HOMEPAGE_RSS_BLOG_TITLE, "Privacy Guides blog feed" ]
|
||||
- title: !ENV [HOMEPAGE_RSS_BLOG_TITLE, "Privacy Guides blog feed"]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_BLOG_LINK,
|
||||
"https://www.privacyguides.org/articles/feed_rss_created.xml",
|
||||
]
|
||||
- title: !ENV [ HOMEPAGE_RSS_FORUM_TITLE, "Latest Privacy Guides forum topics" ]
|
||||
link: !ENV [ HOMEPAGE_RSS_FORUM_LINK, "https://discuss.privacyguides.net/latest.rss" ]
|
||||
- title: !ENV [ HOMEPAGE_RSS_CHANGELOG_TITLE, "Privacy Guides release changelog" ]
|
||||
- title:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_FORUM_TITLE,
|
||||
"Latest Privacy Guides forum topics",
|
||||
]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_FORUM_LINK,
|
||||
"https://discuss.privacyguides.net/latest.rss",
|
||||
]
|
||||
- title:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_CHANGELOG_TITLE,
|
||||
"Privacy Guides release changelog",
|
||||
]
|
||||
link:
|
||||
!ENV [
|
||||
HOMEPAGE_RSS_CHANGELOG_LINK,
|
||||
@@ -145,29 +170,29 @@ extra:
|
||||
]
|
||||
translation_notice:
|
||||
notice: !ENV TRANSLATION_NOTICE
|
||||
cta: !ENV [ TRANSLATION_NOTICE_CTA, "Visit Crowdin" ]
|
||||
cta: !ENV [TRANSLATION_NOTICE_CTA, "Visit Crowdin"]
|
||||
language: !ENV SITE_LANGUAGE_ENGLISH
|
||||
translation_stylesheet: !ENV [ TRANSLATION_STYLESHEET ]
|
||||
translation_stylesheet: !ENV [TRANSLATION_STYLESHEET]
|
||||
social:
|
||||
- icon: simple/mastodon
|
||||
link: https://mastodon.neat.computer/@privacyguides
|
||||
name: !ENV [ SOCIAL_MASTODON, "Mastodon" ]
|
||||
name: !ENV [SOCIAL_MASTODON, "Mastodon"]
|
||||
- icon: simple/peertube
|
||||
link: https://neat.tube/c/privacyguides
|
||||
name: !ENV [ SOCIAL_PEERTUBE, "PeerTube" ]
|
||||
name: !ENV [SOCIAL_PEERTUBE, "PeerTube"]
|
||||
- icon: simple/matrix
|
||||
link: https://matrix.to/#/#privacyguides:matrix.org
|
||||
name: !ENV [ SOCIAL_MATRIX, "Matrix" ]
|
||||
name: !ENV [SOCIAL_MATRIX, "Matrix"]
|
||||
- icon: simple/discourse
|
||||
link: https://discuss.privacyguides.net/
|
||||
name: !ENV [ SOCIAL_FORUM, "Forum" ]
|
||||
name: !ENV [SOCIAL_FORUM, "Forum"]
|
||||
- icon: simple/github
|
||||
link: https://github.com/privacyguides
|
||||
name: !ENV [ SOCIAL_GITHUB, "GitHub" ]
|
||||
name: !ENV [SOCIAL_GITHUB, "GitHub"]
|
||||
- icon: simple/torbrowser
|
||||
link: http://www.xoe4vn5uwdztif6goazfbmogh6wh5jc4up35bqdflu6bkdc5cas5vjqd.onion/
|
||||
name: !ENV [ SOCIAL_TOR_SITE, "Hidden service" ]
|
||||
language_switcher: !ENV [ LANGUAGE_SWITCHER, true ]
|
||||
name: !ENV [SOCIAL_TOR_SITE, "Hidden service"]
|
||||
language_switcher: !ENV [LANGUAGE_SWITCHER, true]
|
||||
alternate:
|
||||
- name: English
|
||||
link: /en/
|
||||
@@ -207,46 +232,53 @@ extra:
|
||||
icon: https://raw.githubusercontent.com/twitter/twemoji/master/assets/svg/1f1f7-1f1fa.svg
|
||||
analytics:
|
||||
feedback:
|
||||
title: !ENV [ ANALYTICS_FEEDBACK_TITLE, "Was this page helpful?" ]
|
||||
title: !ENV [ANALYTICS_FEEDBACK_TITLE, "Was this page helpful?"]
|
||||
ratings:
|
||||
- icon: material/emoticon-happy-outline
|
||||
name: !ENV [ ANALYTICS_FEEDBACK_POSITIVE_NAME, "This page was helpful" ]
|
||||
name: !ENV [ANALYTICS_FEEDBACK_POSITIVE_NAME, "This page was helpful"]
|
||||
data: 1
|
||||
note: !ENV [ ANALYTICS_FEEDBACK_POSITIVE_NOTE, "Thanks for your feedback!" ]
|
||||
note:
|
||||
!ENV [ANALYTICS_FEEDBACK_POSITIVE_NOTE, "Thanks for your feedback!"]
|
||||
- icon: material/emoticon-sad-outline
|
||||
name: !ENV [ ANALYTICS_FEEDBACK_NEGATIVE_NAME, "This page could be improved" ]
|
||||
name:
|
||||
!ENV [
|
||||
ANALYTICS_FEEDBACK_NEGATIVE_NAME,
|
||||
"This page could be improved",
|
||||
]
|
||||
data: 0
|
||||
note: !ENV [ ANALYTICS_FEEDBACK_NEGATIVE_NOTE, "Thanks for your feedback!" ]
|
||||
note:
|
||||
!ENV [ANALYTICS_FEEDBACK_NEGATIVE_NOTE, "Thanks for your feedback!"]
|
||||
|
||||
repo_url: !ENV [ BUILD_REPO_URL, "https://github.com/privacyguides/privacyguides.org" ]
|
||||
repo_url:
|
||||
!ENV [BUILD_REPO_URL, "https://github.com/privacyguides/privacyguides.org"]
|
||||
repo_name: ""
|
||||
|
||||
theme:
|
||||
name: material
|
||||
language: !ENV [ BUILD_THEME_LANGUAGE, "en" ]
|
||||
language: !ENV [BUILD_THEME_LANGUAGE, "en"]
|
||||
custom_dir: theme
|
||||
font:
|
||||
text: !ENV [ BUILD_THEME_FONT_TEXT, "Public Sans" ]
|
||||
code: !ENV [ BUILD_THEME_FONT_CODE, "DM Mono" ]
|
||||
text: !ENV [BUILD_THEME_FONT_TEXT, "Public Sans"]
|
||||
code: !ENV [BUILD_THEME_FONT_CODE, "DM Mono"]
|
||||
palette:
|
||||
- media: "(prefers-color-scheme)"
|
||||
scheme: default
|
||||
accent: deep purple
|
||||
toggle:
|
||||
icon: material/brightness-auto
|
||||
name: !ENV [ THEME_DARK, "Switch to dark mode" ]
|
||||
name: !ENV [THEME_DARK, "Switch to dark mode"]
|
||||
- media: "(prefers-color-scheme: dark)"
|
||||
scheme: slate
|
||||
accent: amber
|
||||
toggle:
|
||||
icon: material/brightness-2
|
||||
name: !ENV [ THEME_LIGHT, "Switch to light mode" ]
|
||||
name: !ENV [THEME_LIGHT, "Switch to light mode"]
|
||||
- media: "(prefers-color-scheme: light)"
|
||||
scheme: default
|
||||
accent: deep purple
|
||||
toggle:
|
||||
icon: material/brightness-5
|
||||
name: !ENV [ THEME_AUTO, "Switch to system theme" ]
|
||||
name: !ENV [THEME_AUTO, "Switch to system theme"]
|
||||
favicon: assets/brand/logos/png/favicon-32x32.png
|
||||
icon:
|
||||
repo: simple/github
|
||||
@@ -278,29 +310,29 @@ plugins:
|
||||
tags: {}
|
||||
search: {}
|
||||
privacy:
|
||||
enabled: !ENV [ BUILD_PRIVACY, true ]
|
||||
enabled: !ENV [BUILD_PRIVACY, true]
|
||||
offline:
|
||||
enabled: !ENV [ BUILD_OFFLINE, false ]
|
||||
enabled: !ENV [BUILD_OFFLINE, false]
|
||||
group:
|
||||
enabled: !ENV [ BUILD_INSIDERS, false ]
|
||||
enabled: !ENV [BUILD_INSIDERS, false]
|
||||
plugins:
|
||||
macros: {}
|
||||
meta: {}
|
||||
git-authors:
|
||||
enabled: !ENV [ GITAUTHORS, PRODUCTION, NETLIFY, false ]
|
||||
enabled: !ENV [GITAUTHORS, PRODUCTION, NETLIFY, false]
|
||||
sort_authors_by: contribution
|
||||
show_contribution: true
|
||||
fallback_to_empty: true
|
||||
authorship_threshold_percent: 1
|
||||
git-revision-date-localized:
|
||||
enabled: !ENV [ GITREVISIONDATE, PRODUCTION, NETLIFY, false ]
|
||||
enabled: !ENV [GITREVISIONDATE, PRODUCTION, NETLIFY, false]
|
||||
exclude:
|
||||
- index.md
|
||||
fallback_to_build_date: true
|
||||
enable_creation_date: true
|
||||
typeset: {}
|
||||
social:
|
||||
cards: !ENV [ CARDS, true ]
|
||||
cards: !ENV [CARDS, true]
|
||||
cards_dir: assets/img/social
|
||||
cards_layout_dir: theme/layouts
|
||||
cards_layout: page
|
||||
@@ -325,7 +357,7 @@ markdown_extensions:
|
||||
pymdownx.tilde: {}
|
||||
pymdownx.snippets:
|
||||
auto_append:
|
||||
- !ENV [ BUILD_ABBREVIATIONS, "includes/abbreviations.en.txt" ]
|
||||
- !ENV [BUILD_ABBREVIATIONS, "includes/abbreviations.en.txt"]
|
||||
pymdownx.tasklist:
|
||||
custom_checkbox: true
|
||||
attr_list: {}
|
||||
@@ -345,50 +377,49 @@ markdown_extensions:
|
||||
toc_depth: 4
|
||||
|
||||
nav:
|
||||
- ? !ENV [ NAV_HOME, "Home" ]
|
||||
: "index.md"
|
||||
- ? !ENV [ NAV_KNOWLEDGE_BASE, "Knowledge Base" ]
|
||||
: - "basics/why-privacy-matters.md"
|
||||
- !ENV [NAV_HOME, "Home"]: "index.md"
|
||||
- !ENV [NAV_KNOWLEDGE_BASE, "Knowledge Base"]:
|
||||
- "basics/why-privacy-matters.md"
|
||||
- "basics/threat-modeling.md"
|
||||
- "basics/common-threats.md"
|
||||
- "basics/common-misconceptions.md"
|
||||
- "basics/account-creation.md"
|
||||
- "basics/account-deletion.md"
|
||||
- ? !ENV [ NAV_TECHNOLOGY_ESSENTIALS, "Technology Essentials" ]
|
||||
: - "basics/passwords-overview.md"
|
||||
- !ENV [NAV_TECHNOLOGY_ESSENTIALS, "Technology Essentials"]:
|
||||
- "basics/passwords-overview.md"
|
||||
- "basics/multi-factor-authentication.md"
|
||||
- "basics/hardware.md"
|
||||
- "basics/email-security.md"
|
||||
- "basics/vpn-overview.md"
|
||||
- ? !ENV [ NAV_ADVANCED_TOPICS, "Advanced Topics" ]
|
||||
: - "advanced/dns-overview.md"
|
||||
- !ENV [NAV_ADVANCED_TOPICS, "Advanced Topics"]:
|
||||
- "advanced/dns-overview.md"
|
||||
- "advanced/tor-overview.md"
|
||||
- "advanced/payments.md"
|
||||
- "advanced/communication-network-types.md"
|
||||
- ? !ENV [ NAV_OPERATING_SYSTEMS, "Operating Systems" ]
|
||||
: - "os/index.md"
|
||||
- !ENV [NAV_OPERATING_SYSTEMS, "Operating Systems"]:
|
||||
- "os/index.md"
|
||||
- "os/android-overview.md"
|
||||
- "os/ios-overview.md"
|
||||
- "os/linux-overview.md"
|
||||
- "os/macos-overview.md"
|
||||
- "os/qubes-overview.md"
|
||||
- ? !ENV [ NAV_OPERATING_SYSTEMS_WINDOWS, "Windows" ]
|
||||
: - "os/windows/index.md"
|
||||
- !ENV [NAV_OPERATING_SYSTEMS_WINDOWS, "Windows"]:
|
||||
- "os/windows/index.md"
|
||||
- "os/windows/group-policies.md"
|
||||
- ? !ENV [ NAV_RECOMMENDATIONS, "Recommendations" ]
|
||||
: - "tools.md"
|
||||
- ? !ENV [ NAV_SELF_HOSTING, "Self-Hosting" ]
|
||||
: - "self-hosting/index.md"
|
||||
- !ENV [NAV_RECOMMENDATIONS, "Recommendations"]:
|
||||
- "tools.md"
|
||||
- !ENV [NAV_SELF_HOSTING, "Self-Hosting"]:
|
||||
- "self-hosting/index.md"
|
||||
- "self-hosting/dns-filtering.md"
|
||||
- "self-hosting/email-servers.md"
|
||||
- "self-hosting/file-management.md"
|
||||
- ? !ENV [ NAV_INTERNET_BROWSING, "Internet Browsing" ]
|
||||
: - "tor.md"
|
||||
- !ENV [NAV_INTERNET_BROWSING, "Internet Browsing"]:
|
||||
- "tor.md"
|
||||
- "desktop-browsers.md"
|
||||
- "mobile-browsers.md"
|
||||
- "browser-extensions.md"
|
||||
- ? !ENV [ NAV_PROVIDERS, "Providers" ]
|
||||
: - "cloud.md"
|
||||
- !ENV [NAV_PROVIDERS, "Providers"]:
|
||||
- "cloud.md"
|
||||
- "data-broker-removals.md"
|
||||
- "dns.md"
|
||||
- "email-aliasing.md"
|
||||
@@ -397,8 +428,8 @@ nav:
|
||||
- "photo-management.md"
|
||||
- "search-engines.md"
|
||||
- "vpn.md"
|
||||
- ? !ENV [ NAV_SOFTWARE, "Software" ]
|
||||
: - "ai-chat.md"
|
||||
- !ENV [NAV_SOFTWARE, "Software"]:
|
||||
- "ai-chat.md"
|
||||
- "calendar.md"
|
||||
- "cryptocurrency.md"
|
||||
- "data-redaction.md"
|
||||
@@ -418,24 +449,25 @@ nav:
|
||||
- "pastebins.md"
|
||||
- "real-time-communication.md"
|
||||
- "social-networks.md"
|
||||
- ? !ENV [ NAV_HARDWARE, "Hardware" ]
|
||||
: - "mobile-phones.md"
|
||||
- !ENV [NAV_HARDWARE, "Hardware"]:
|
||||
- "hardware-wallets.md"
|
||||
- "mobile-phones.md"
|
||||
- "security-keys.md"
|
||||
- ? !ENV [ NAV_OPERATING_SYSTEMS, "Operating Systems" ]
|
||||
: - ? !ENV [ NAV_ANDROID, "Android" ]
|
||||
: - "android/index.md"
|
||||
- !ENV [NAV_OPERATING_SYSTEMS, "Operating Systems"]:
|
||||
- !ENV [NAV_ANDROID, "Android"]:
|
||||
- "android/index.md"
|
||||
- "android/distributions.md"
|
||||
- "android/general-apps.md"
|
||||
- "android/obtaining-apps.md"
|
||||
- "desktop.md"
|
||||
- "router.md"
|
||||
- ? !ENV [ NAV_ADVANCED, "Advanced" ]
|
||||
: - "alternative-networks.md"
|
||||
- !ENV [NAV_ADVANCED, "Advanced"]:
|
||||
- "alternative-networks.md"
|
||||
- "device-integrity.md"
|
||||
- ? !ENV [ NAV_ACTIVISM, "Activism" ]
|
||||
: - "activism/index.md"
|
||||
- ? !ENV [ NAV_ACTIVISM_TOOLBOX, "Activist Toolbox" ]
|
||||
: - "activism/toolbox/index.md"
|
||||
- !ENV [NAV_ACTIVISM, "Activism"]:
|
||||
- "activism/index.md"
|
||||
- !ENV [NAV_ACTIVISM_TOOLBOX, "Activist Toolbox"]:
|
||||
- "activism/toolbox/index.md"
|
||||
- "Check Your Laws":
|
||||
- "activism/toolbox/tip-know-your-privacy-laws.md"
|
||||
- "activism/toolbox/tip-report-privacy-violations.md"
|
||||
@@ -472,48 +504,43 @@ nav:
|
||||
- "Take Action!":
|
||||
- "activism/toolbox/tip-engage-boosts-and-contribute.md"
|
||||
- "activism/toolbox/tip-level-up-assemble-and-organize.md"
|
||||
- ? !ENV [ NAV_ACTIVISM_LEGAL, "Legal Resources" ]
|
||||
: - "activism/legal/dpa-directory.md"
|
||||
- ? !ENV [ NAV_BLOG, "Articles" ]
|
||||
: !ENV [ ARTICLES_SITE_BASE_URL, "/articles/" ]
|
||||
- ? !ENV [ NAV_VIDEOS, "Videos" ]
|
||||
: !ENV [ VIDEOS_SITE_BASE_URL, "/videos/" ]
|
||||
- ? !ENV [ NAV_NEWS, "News" ]
|
||||
: !ENV [ NEWS_SITE_BASE_URL, "/news/" ]
|
||||
- ? !ENV [ NAV_FORUM, "Forum" ]
|
||||
: !ENV [ NAV_FORUM_LINK, "https://discuss.privacyguides.net/" ]
|
||||
- ? !ENV [ NAV_WIKI, "Wiki" ]
|
||||
: !ENV [
|
||||
- !ENV [NAV_ACTIVISM_LEGAL, "Legal Resources"]:
|
||||
- "activism/legal/dpa-directory.md"
|
||||
- !ENV [NAV_BLOG, "Articles"]: !ENV [ARTICLES_SITE_BASE_URL, "/articles/"]
|
||||
- !ENV [NAV_VIDEOS, "Videos"]: !ENV [VIDEOS_SITE_BASE_URL, "/videos/"]
|
||||
- !ENV [NAV_NEWS, "News"]: !ENV [NEWS_SITE_BASE_URL, "/news/"]
|
||||
- !ENV [NAV_FORUM, "Forum"]:
|
||||
!ENV [NAV_FORUM_LINK, "https://discuss.privacyguides.net/"]
|
||||
- !ENV [NAV_WIKI, "Wiki"]:
|
||||
!ENV [
|
||||
NAV_WIKI_LINK,
|
||||
"https://discuss.privacyguides.net/c/community-wiki/9411/none",
|
||||
]
|
||||
- ? !ENV [ NAV_ABOUT, "About" ]
|
||||
: - "about.md"
|
||||
- !ENV [NAV_ABOUT, "About"]:
|
||||
- "about.md"
|
||||
- "about/donate.md"
|
||||
- ? !ENV [ NAV_ABOUT_TEAM_MEMBERS, "Team Members" ]
|
||||
: https://discuss.privacyguides.net/u?group=team&order=solutions&period=all
|
||||
- ? !ENV [ NAV_ABOUT_POLICIES, "Policies" ]
|
||||
: - "about/criteria.md"
|
||||
- !ENV [NAV_ABOUT_TEAM_MEMBERS, "Team Members"]:
|
||||
https://discuss.privacyguides.net/u?group=team&order=solutions&period=all
|
||||
- !ENV [NAV_ABOUT_POLICIES, "Policies"]:
|
||||
- "about/criteria.md"
|
||||
- "about/donation-acceptance-policy.md"
|
||||
- "about/executive-policy.md"
|
||||
- "privacy.md"
|
||||
- "about/notices.md"
|
||||
- ? !ENV [ NAV_COMMUNITY, "Community" ]
|
||||
: - "about/jobs.md"
|
||||
- !ENV [NAV_COMMUNITY, "Community"]:
|
||||
- "about/jobs.md"
|
||||
- "about/contributors.md"
|
||||
- ? !ENV [ NAV_ONLINE_SERVICES, "Online Services" ]
|
||||
: "about/services.md"
|
||||
- ? !ENV [ NAV_CODE_OF_CONDUCT, "Code of Conduct" ]
|
||||
: "CODE_OF_CONDUCT.md"
|
||||
- !ENV [NAV_ONLINE_SERVICES, "Online Services"]: "about/services.md"
|
||||
- !ENV [NAV_CODE_OF_CONDUCT, "Code of Conduct"]: "CODE_OF_CONDUCT.md"
|
||||
- "about/statistics.md"
|
||||
- ? !ENV [ NAV_CONTRIBUTING, "Contributing" ]
|
||||
: - ? !ENV [ NAV_WRITING_GUIDE, "Writing Guide" ]
|
||||
: - "meta/writing-style.md"
|
||||
- !ENV [NAV_CONTRIBUTING, "Contributing"]:
|
||||
- !ENV [NAV_WRITING_GUIDE, "Writing Guide"]:
|
||||
- "meta/writing-style.md"
|
||||
- "meta/admonitions.md"
|
||||
- "meta/brand.md"
|
||||
- "meta/translations.md"
|
||||
- ? !ENV [ NAV_TECHNICAL_GUIDES, "Technical Guides" ]
|
||||
: - "meta/uploading-images.md"
|
||||
- !ENV [NAV_TECHNICAL_GUIDES, "Technical Guides"]:
|
||||
- "meta/uploading-images.md"
|
||||
- "meta/git-recommendations.md"
|
||||
- "meta/commit-messages.md"
|
||||
- "meta/pr-comments.md"
|
||||
|
||||
Reference in New Issue
Block a user